Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers
ID: 6f4b81b7-d2bc-5310-a7a4-476a3a5e0d4b
STIX ID: report--6f4b81b7-d2bc-5310-a7a4-476a3a5e0d4b
Feed Name: Fortinet Blog
FortiGuard Labs observed a Casbaneiro malware campaign in August 2026 targeting Latin American users via phishing PDFs and HTA/AutoIt-based multi-stage delivery; the malware performs email and credential theft, uses process injection and persistence via Startup LNK and markers under %PUBLIC%/%APPDATA%, employs targeted C2 activation when victims visit banking sites, and leverages stealthy network behaviors (403 responses, malformed HTTP packets) to evade analysis; the report includes detailed IOCs (hashes, domains, IPs), mitigations, and Fortinet detection names.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
